← ClaudeAtlas

awesome-dependency-auditlisted

Read-only supply-chain audit of packages and agent extensions: lockfiles, typosquats, dependency confusion, install scripts, licenses, CVEs. Use when asked if a package, manifest change or bot bump is safe.
khasky/awesome-agent-skills · ★ 10 · AI & Automation · score 79
Install: claude install-skill khasky/awesome-agent-skills
# Dependency Audit Audit the third-party dependency graph — manifests, lockfiles, and the packages they resolve to — for supply-chain risk, before it ships with the product. Read-only: it reports findings and a verdict; it does not upgrade, pin, or remove anything. To act on the report, call the Skill tool with "awesome-dependency-upgrade". Two phases: passive (reading manifests, lockfiles, license files, changelogs already on disk — no gate) and active (anything that reaches a registry or scanner: `npm audit`, `pip-audit`, `osv-scanner`, registry metadata lookups — propose the commands and wait for approval first). Default to passive; say what staying passive leaves unverified. ## Scope and method 1. Establish scope — the whole graph, one manifest, or one diff (a bot bump, a new package). Name the ecosystems found (`package.json`, `requirements.txt`/`pyproject.toml`, `go.mod`, `Cargo.toml`, `pom.xml`/`gradle`, `Gemfile`). Include the repo's agent extensions in the graph when present — `.claude/`, `.agents/`, `.cursor/`, `.gemini/` skill and plugin folders, `.mcp.json` and equivalent MCP server lists, plugin-marketplace references, and any agent hook manifest. They install and execute on a contributor's machine exactly like a dependency, and no scanner covers them (Track C). 2. Gather evidence — manifests + lockfiles + install configuration (`.npmrc`, `pip.conf`, registry settings) + CI install commands. Every finding cites a file, a line, a version, or a scanner line — n